[PATCH security v1] apparmor: fix a use-after-free in aa_lookupn_ns()

sashiko-bot at kernel.org sashiko-bot at kernel.org
Wed Sep 23 05:56:33 UTC 2026


> aa_lookupn_ns() takes a reference on the namespace it finds with
> aa_get_ns(),which is kref_get() on the reference count that the
> namespace is released through, without checking whether the namespace
> is still in use.  A concurrent removal of a ":"-prefixed namespace
> looks the same namespace up and only then takes the parent lock to
> remove it, so the last reference can be dropped between the lookup and
> the aa_get_ns() call: the reference count then reports the increment on
> a zero count and the kernel classifies the following use of the object
> as a use-after-free.  A user with CAP_MAC_ADMIN can trigger this by
> writing a ":<name>" removal and a ":<name>/<profile>" removal to
> /sys/kernel/security/apparmor/.remove concurrently.
> 
> refcount_t: addition on 0; use-after-free.
> WARNING: lib/refcount.c:25 at refcount_warn_saturate+0xc0/0xe0, CPU#6
> Call Trace:
> [ ... ]
> 
> Fix by rejecting a namespace whose reference count.
> 
> Fixes: 3664268f19ea0 ("apparmor: add namespace lookup fns()")
> Signed-off-by: Binbin Deng <18983559317 at 163.com>

Sashiko has reviewed this patch and found no issues. It looks great!

-- 
Sashiko AI review · https://sashiko.dev/#/patchset/20260923054623.247634-1-18983559317@163.com?part=1




More information about the Linux-security-module-archive mailing list